Model
NVIDIA Nemotron 3 Ultra
Openness
open_weights_recipe
Licence
OpenMDW License Agreement v1.1 (OpenMDW-1.1)
Ultra is the one Nemotron 3 release whose ownership reaches substantial: the OpenMDW 'deal without restriction' grant makes use-and-modify strong, self-hosting via NIM makes data control strong, and the open_weights_recipe transparency is strong - so you can use it, see it and keep your data outright. It stops short of full because reliability is only moderate: there is no dedicated model-level safety evaluation, and at 550B / 55B active it is a multi-node deployment. Self-host, assemble the downloadable guard stack, red-team for your own use case, and treat EU systemic-risk status as unresolved until NVIDIA discloses training compute.
Do you really own it?
Substantial
none·limited·partial·substantial·full
Analytical input: AOI C · 63.6/100
The four ownership factors
Floor-weighted, not averaged. Nothing is weak and both use & modify and data control are strong, so the floor is high; reliability sits at moderate, which is what keeps it short of full.
1
Use and modify freelyCan you run, modify and adapt it with no gate and no field-of-use trap?
StrongUltra is under OpenMDW-1.1, whose grant is to 'deal in the Model Materials without restriction' - an MIT/BSD-style, unconditional permission covering weights, data, documentation and software, with commercial use allowed and no acceptable-use or field-of-use limit. Weights are ungated and fine-tunable. The only condition is a defensive litigation termination (with a first-sued carve-out), which does not restrict ordinary use or modification. This is the permissive-open case, and the reason Ultra is the family member that reaches strong here.
How this scores (AOI sub-dimensions)
Openness4/5how much is released - weights, data, code, licence - and how freelyOpen weights plus recipe: ungated safetensors weights, a representative training recipe (Pretrain -> SFT -> MOPD -> Quant), a white paper, and post-training data under CC-BY-4.0 put Ultra at the open_weights_recipe tier.
Legal3/5how permissive and clean the licence is for real commercial useUltra carries the most permissive licence in the family: OpenMDW-1.1 grants the right to "deal in the Model Materials without restriction", covering weights, data, documentation and software, with only a defensive patent/copyright-litigation termination.
2
TransparencyDo you know what it is: weights, training, behaviour, and legible terms?
Strongopen_weights_recipe: ungated weights, a white paper and a representative training recipe with CC-BY post-training data let you see a great deal of how Ultra was built. The limit is reproducibility, not visibility - the intermediate checkpoints and the 1M-context data are not open - which caps the openness tier, not transparency.
How this scores (AOI sub-dimensions)
Provenance3/5how well we can trace and verify what went into the modelDistributed from the verified nvidia org on Hugging Face as ungated safetensors with official BF16 / NVFP4 quantization variants and a clear canonical source (checklist ~4/8).
Governance3/5how accountable and well-documented the publisher isA reputable, accountable publisher (NVIDIA) with a white paper, a verified hub presence and an active release cadence, and a general corporate security-reporting path.
3
ReliabilityIs it reliable and good enough for the job?
ModerateOperational is 3 (runs on mainstream stacks with official quantizations, but is a multi-node-only 550B model with no small-variant drop-in) and safety is 3 (no dedicated model-level safety evaluation, so misuse control is a gap you must fill yourself). Under the ownership rule, a safety score of 3 caps this factor at moderate.
How this scores (AOI sub-dimensions)
Operational3/5how practical it is to run, serve and maintain in productionRuns on mainstream stacks (vLLM, SGLang, NVIDIA NIM) with official BF16 / NVFP4 quantizations and documented hardware expectations.
Safety3/5whether misuse risks are evaluated and guardrails are providedA safety-tuned release (post-training safety data plus keyword/regex filtering) with the downloadable family guard stack - the Nemotron-3-Content-Safety classifier, the Apache-2.0 NeMo Guardrails toolkit and the Apache-2.0 garak scanner - genuinely attributable to Ultra.
4
Doesn't extract your dataDoes running it keep your knowledge and data yours?
StrongSelf-hosted via NIM, the weights and inference run on your own infrastructure and data never leaves your enclave, and the OpenMDW grant claws back no rights - it is 'without restriction' with only a defensive termination. That is the clearest strong case for data control in the family.
How this scores
Not a scored AOI dimension. For a self-hosted model, data-control is a structural property of running the weights yourself, strong by default unless the model phones home or the licence claws back rights. For a hosted API this factor is the retention + train-on-inputs + residency read, scored from the binding terms.
How the AOI score is computed
The seven dimensions above, each scored 0 to 5, weighted and summed to the 0 to 100 headline. The score is the analytical input behind the ownership verdict, not the verdict itself.
DimensionScoreWeightPoints
Openness4/50.1814.4
Provenance3/50.169.6
Legal3/50.169.6
Safety3/50.169.6
Performance3/50.148.4
Operational3/50.127.2
Governance3/50.084.8
HeadlineC · 63.6/100
Sources
Every rating traces to a primary document. Read means the text was verified; unverified means it is known to exist but has not yet been read.
DocumentWhat it grounds
Model cardread2026-08-03
Nemotron 3 Ultra model card on the verified nvidia HF org: 550B total / 55B active; Mamba2-Transformer hybrid LatentMoE + MTP; up to 1M context; ~20T training tokens; ungated safetensors with BF16/NVFP4 variants; card states "open models with open weights, training data, and recipes"; licence tag openmdw-1.1.
Licenceread2026-08-03
OpenMDW License Agreement v1.1, read: "permission is hereby granted, free of charge, to deal in the Model Materials without restriction, including under all copyright, patent, database, and trade secret rights"; "Model Materials" covers weights, data, documentation and software.
Documentationread2026-08-03
Ultra training recipe at github.com/NVIDIA-NeMo/Nemotron (docs/nemotron/ultra3, Pretrain -> SFT -> MOPD -> Quant), read: described as "a representative single pass"; the "intermediate checkpoints it depends on have not been open-sourced" and the "1M-context LC phase is not included because its data ...
Technical_reportread2026-08-03
Nemotron 3 White Paper (arXiv 2512.20856), read: Ultra is a Mamba2-Transformer hybrid LatentMoE, up to 1M context.
Model cardread2026-08-03
Safety, read: no dedicated model-level safety evaluation for Ultra (white paper safety section is a contributor list; safety appears only as post-training data curation - Nemotron Content Safety v2 + Gretel refusal data + keyword/regex filtering).
Documentationread2026-08-03
Verified nvidia org on Hugging Face; the Ultra weight repo is ungated safetensors with published BF16/NVFP4 quantization variants.
Terms of serviceread2026-08-03
NVIDIA NIM is self-hosted deployment tooling ("data never leaves your secure enclave"), so NVIDIA is not an AOI inference-provider entry and self-hosting Ultra supports data control.
Third-party analysisread2026-08-03
NVIDIA is NOT a signatory to the EU GPAI Code of Practice (EU signatory list), and no NVIDIA training-content summary or copyright policy for Nemotron was located.